Business path
7 min read
An afternoon security checklist
One afternoon, not a project
Security can feel like something you will get to "properly" one day, which usually means never. So do not treat it as a project. Treat it as one afternoon.
The steps below are all small and finishable. None of them needs a technical person, and none of them needs money. Work down the list, tick each one off, and by the end of the afternoon your business is meaningfully harder to hurt than it was this morning. If a step turns out to be bigger than expected, note it and move on. Done is better than perfect.
Try this now
If you only do one thing from this whole list, do this: turn on multi-factor authentication (MFA) on your single most important account, usually the email address everything else resets to. It takes a few minutes and it is the single most valuable step here. Start it now, then come back and work through the rest.
Turn on multi-factor authentication (MFA)
Multi-factor authentication (MFA) adds a second step to logging in, usually a code on your phone, so a stolen password alone is not enough to get into an account. It is the single biggest improvement most small businesses can make.
Switch it on for your most important accounts first: your main email, your banking, and anything that holds customer data. Your email matters most, because if someone controls your email they can reset the password on almost everything else.
The passwords and MFA lesson goes through this properly, including where to find the setting. For this afternoon, just getting it turned on for your top few accounts is the win.
Give each important account a strong, unique password
If you reuse one password across accounts, then one leak anywhere exposes all of them at once. The fix is a long, unique password on each account that matters.
Nobody can remember a dozen different strong passwords, and you are not meant to. A password manager remembers them for you, so you only have to remember one. Set one up, then let it generate and store a fresh password for each important account as you go. The passwords and MFA lesson covers choosing and using one.
Confirm a backup exists, and that you have restored from it
Think about what you genuinely could not bear to lose: your customer list, your bookings, your accounts, your photos of the work. Now confirm that a copy of each exists somewhere separate from the device it normally lives on.
A backup you have never tested is only a hope. Once, today, actually restore a single file from your backup and open it. If it opens, you know the backup works. If it does not, far better to find out now than on the day you truly need it. The backups lesson goes deeper on setting this up so it keeps running on its own.
Lock every device
Every phone, laptop, and tablet that touches your business should lock with a PIN, a password, or a fingerprint. A device without a lock hands everything on it to whoever finds it.
This takes two minutes per device. Walk around, pick up each one, and confirm it locks when you set it down. Include the older phone in the drawer that still has the business email signed in.
Review who has access, and remove what is not needed
Over time, access spreads. A former helper still shares your inbox, an old supplier still has a login, an app you stopped using still connects to your accounts. Each of these is a door you have stopped watching.
Go through your important accounts and look at who and what has access. Remove anyone who no longer works with you, and disconnect any app or service you no longer use. If you are not sure why something has access, that is usually a good reason to remove it.
Delete customer data you no longer need
The safest data is the data you are not holding. An old contact list you will never use again is not an asset, it is a liability sitting on your device waiting to be exposed.
Take a few minutes to delete customer information you genuinely no longer need. It costs nothing and it shrinks the amount you have to protect. The lesson on protecting customer data explains the habit of collecting less in the first place.
Know how you would report a serious incident
Even careful businesses have bad days. The time to work out your first move is before one arrives, not during the panic.
Make sure you know that you can report a serious incident to the national authority responsible for cybersecurity. You do not need to memorise a procedure this afternoon. Just knowing where you would turn is enough for now. The incident-reporting lesson walks through how and when to do it, and the talk-through drills let you practise a calm response in advance.
Finishing up
That is the afternoon. MFA on your key accounts, strong unique passwords, a tested backup, locked devices, tidy access, less data to protect, and a plan for a bad day. None of it was hard, and together it closes off the most common ways a small business gets hurt. Put a reminder in your calendar to run down this same list again in a few months, and you are done.
Found something unclear, outdated or improvable? Suggest an improvement